Privacy Policy
Last updated: August 2, 2026
Who we are
StackMentor is operated by Julius Cherubini, an individual based at Kivipelto 2, 40520 Jyväskylä, Finland. The privacy contact is support@stackmentor.dev or +358 40 935 2290.
The operator is the controller for direct account, authentication, billing, support, security, and service-operation information. When a school, bootcamp, or other learning institution provides access, that institution normally controls its roster, course, assignment, material, and student learning data. StackMentor processes that data on the institution's instructions under the School Data Processing Addendum. This remains the same whether the institution uses a standard plan or a Custom Program Plan.
Information we process
We receive information from you, from your institution, from your use of the service, and from the devices and integrations you choose to connect.
- Name, email address, sign-in status, profile changes, and the time and document versions recorded when you accept the Terms and Privacy Policy.
- School and course information, including memberships, roles, invites, assignments, course materials, and usage totals.
- Billing information such as billing email, subscription, seat information, billing period, payment status, and provider IDs. Stripe handles card details on its payment pages.
- Mentor messages, chat history, selected school, course and assignment, mentor replies, cancelled drafts, and course-material context.
- VS Code context needed for a request, including selected code, nearby code, file paths, visible editor content, opened-tab paths, and bounded code ranges requested by the mentor flow.
- Operational and support information such as request paths, status codes, timing, request IDs, rate-limiting IP addresses, job and invoice IDs, provider usage totals, and support messages.
How we use information
We use information only as needed to provide, secure, support, bill, and legally operate StackMentor. We do not use customer content for advertising, targeted marketing, profiling, AI model training, or unrelated product research.
- Direct account data is used to provide the service and manage your account.
- Institution data is processed on the institution's instructions for the educational service.
- Security and operational data is used to prevent abuse, enforce access and usage rules, troubleshoot failures, and protect users.
- Billing records are used to provide paid access and meet accounting, tax, payment, and legal obligations.
We do not use optional website analytics, advertising trackers, or extension telemetry. Essential authentication, security, and preference storage may be used to make the service work.
Schools, bootcamps, and students
School owners and teachers can manage members, courses, assignments, and course materials according to their roles. Teachers cannot use Mentor chat and the current product does not give them individual student conversations. StackMentor operational access is limited to support, security, reliability, legal compliance, and deletion work.
An institution may use a standard plan or a Custom Program Plan. A custom order may define the service term, permitted schools or courses, retention period, deletion process, or institution-specific instructions. It does not change the institution's responsibility to provide any required notices, permissions, or academic rules.
StackMentor is available only to people aged 13 or older. We do not knowingly accept users under 13. Institutions are responsible for deciding whether their students may use the service and for giving any institution-specific notices or permissions they require.
Providers and AI processing
Production providers currently include Vercel, Render, Resend, Supabase, Stripe, OpenRouter, Upstash. Their roles are described on the Subprocessor List.
Supabase is the main authentication and database service, with the production Supabase project located in Ireland. Render's production region and some other provider locations may vary by deployment and are not guaranteed to be in Ireland.
Mentor, Scout, summarisation, and embedding requests may send the relevant message, code, assignment, conversation, or material content through OpenRouter to configured model providers. Requests are routed using zero-data-retention provider settings. Do not send passwords, private keys, access tokens, or other secrets.
Providers may process information outside the European Economic Area or the United Kingdom. Where required, we use an applicable transfer mechanism and provide more information on request.
Cookies and local storage
The web application uses an essential HTTP-only refresh cookie named stackmentor_refresh. It is used only to keep a signed-in web session working and is configured with a 30-day maximum age. Access tokens remain in browser memory. The extension stores its session in VS Code secret storage.
Retention and deletion
User-visible conversations, course materials, assignments, account data, and school data remain while the related account or institution is active and until deletion is requested or required by the institution. A Custom Program Plan Order may define a more specific service term, deletion request process, or retention period for institution data. Billing and legal records may be kept longer when law requires it.
Completed and cancelled mentor jobs are cleaned up after 30 days, failed jobs after 90 days, Scout cache data after 7 days, and accepted, declined, revoked, or expired invites after 30 days. Backups and provider records may remain for their documented backup or legal retention period.
Raw Stripe webhook payloads are reduced to limited billing fields after 30 days. Webhook records other than paid-invoice records are removed after 90 days. Minimized paid-invoice records may be kept for up to seven years for accounting and legal obligations.
You can request deletion or access by emailing support@stackmentor.dev. Account deletion is also available in the product when its ownership and school-membership requirements are satisfied. School deletion may be delayed until billing closeout and required legal retention are complete.
Your rights
Depending on the applicable law and the institution's role, you may have rights to access, correct, delete, restrict, object to, or receive your personal information, withdraw consent, and complain to a data-protection authority. Send requests to support@stackmentor.dev. We may verify identity and respond within the time required by applicable law.
Security incidents
Report suspected security or privacy incidents immediately to support@stackmentor.dev. We investigate, document, and notify the relevant institution or people without undue delay when required. More information is available on the Security page.
Changes and contact
We may update this policy when the service, providers, or legal requirements change. We will post the updated policy here and change the date above. Questions about privacy, student data, providers, or deletion can be sent to support@stackmentor.dev.